Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k
2 months ago
packetfence preview

packetfence

GitHubinverse-inc/packetfence

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

authentication-authorizationconfiguration-auditingdefensive-tools+6
1.7k4 days ago
macOS-enterprise-privileges preview

macOS-enterprise-privileges

GitHubsap/macos-enterprise-privileges

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

authentication-authorizationconfiguration-auditingdefensive-tools+2
2.0k6 days ago
jsch preview

jsch

GitHubmwiede/jsch

fork of the popular jsch library

authentication-authorizationencryption-decryption-toolsnetwork-security+2
1.1k11 days ago
awesome-entra preview

awesome-entra

GitHubmerill/awesome-entra

😎 Awesome list of all things related to Microsoft Entra

authentication-authorizationcloud-securityconfiguration-auditing+5
7733 months ago
heimdal preview

heimdal

GitHubheimdal/heimdal

Implementation of Kerberos, PKI, and ASN.1/DER providing authentication, authorization, and cryptographic services for secure networks.

authentication-authorizationcryptographyencryption-decryption-tools+3
37010 days ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
CertificateDsc preview

CertificateDsc

GitHubdsccommunity/certificatedsc

DSC resources to simplify administration of certificates on a Windows Server.

authentication-authorizationcloud-infrastructure-securityconfiguration-auditing+3
1257 months ago
aad-sso-enum-brute-spray preview

aad-sso-enum-brute-spray

GitHubtreebuilder/aad-sso-enum-brute-spray

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

authentication-authorizationcloud-securityinformation-gathering+3
1934 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubaydinnyunus/cve-2025-29927

CVE-2025-29927 Proof of Concept

authentication-authorizationeducationexploitation+3
1031 year ago
shiro-cve-2020-17523 preview

shiro-cve-2020-17523

GitHubjweny/shiro-cve-2020-17523

Analysis of two authentication bypass techniques for Apache Shiro (CVE-2020-17523) with a reproducible exploit environment and detailed root cause…

authentication-authorizationeducationlabs-practice+3
1185 years ago
CVE-2021-24085 preview

CVE-2021-24085

GitHubsourceincite/cve-2021-24085

Proof-of-concept exploit for CVE-2021-24085: CSRF-based elevation of privilege in Microsoft Exchange Server via msExchEcpCanary token forgery,…

authentication-authorizationexploitationpenetration-testing+2
715 years ago
connectwise-screenconnect_auth-bypass-add-user-poc preview

connectwise-screenconnect_auth-bypass-add-user-poc

GitHubwatchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc

Proof-of-concept exploit for authentication bypass in ConnectWise ScreenConnect, enabling addition of administrative user as first step to Remote…

authentication-authorizationexploitationprivilege-escalation+3
752 years ago
MakerChecker preview

MakerChecker

GitHubmakerchecker/makerchecker

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

ai-securityauthentication-authorizationcloud-security+7
522 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubimmersive-labs-sec/cve-2025-31161

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

authentication-authorizationexploitationpenetration-testing+3
481 year ago
CVE-2020-15906 preview

CVE-2020-15906

GitHubs1lkys/cve-2020-15906

Writeup of CVE-2020-15906

authentication-authorizationexploitationpassword-attacks+3
515 years ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubmalwareman007/cve-2022-36537

POC of CVE-2022-36537

authentication-authorizationexploitationinformation-gathering+3
361 year ago
CVE-2023-46805_CVE-2024-21887 preview

CVE-2023-46805_CVE-2024-21887

GitHubduy-31/cve-2023-46805_cve-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access…

authentication-authorizationcommand-and-controlexploitation+3
232 years ago
Previous1234…12Next